CISSP-ISSAP Training & Certification

BY
Infosec Train

Enroll in the CISSP-ISSAP Training & Certification by Infosec Train and learn critical skills to become a certified security architecture professional.

Mode

Online

Quick Facts

particular details
Medium of instructions English
Mode of learning Self study, Virtual Classroom
Mode of Delivery Video and Text Based

Course overview

The CISSP-ISSAP training course is a comprehensive certification course, which will help you gain risk-based guidance to address the various organisational safety goals. It will be 32 hours of instructor-led training and feature a blended learning delivery model. The CISSP-ISSAP course will shape you as an information security architect or analyst. Through the programme, you will also acquire advance technical competencies to undertake tasks like Business Continuity Planning (BCP), Disaster Recovery Planning (DRP), and Business Impact Analysis (BIA).

Also, you will become proficient in the critical concepts of access management architecture, access control systems, and techniques. The extensive CISSP-ISSAP syllabus will offer in-depth knowledge of communication products, cryptography, security architecture, recovery solutions, and physical security considerations.

As such, the training will make you skilled at executing various analytical and information security processes. Finally, you must take the CISSP-ISSAP certification exam when the course ends and score the passing marks to qualify for the certificate.

The highlights

  • Experienced instructors
  • Accredited by EC-Council 
  • Different learning modes
  • Flexible schedule 
  • Tailor-made training
  • Blended learning model
  • 32 hrs of instructor-led training
  • Training certificate
  • Post-training support

Program offerings

  • Tailor-made training
  • Blended learning model
  • Experienced instructors
  • Training certificate
  • Instructor-led learning
  • Accredited by infosec train.

Course and certificate fees

certificate availability

Yes

certificate providing authority

Infosec Train

Who it is for

Doing the CISSP-ISSAP training course by Infosec Train will advance the technical skills of the following professionals:

  • System Architects
  • Business Analysts
  • System and Network Designers
  • Chief Security Officers
  • Chief Technology Officers

Eligibility criteria

To enroll in the CISSP-ISSAP certification course, you must possess a minimum of two years of paid work experience (full-time and cumulative) working in at least one of the six CISSP-ISSAP CBK domains.

Moreover, you need to get 700/1000 points in the CISSP-ISSAP certification exam to get the CISSP-ISSAP certificate.

What you will learn

Knowledge of cryptography

Once you've finished the CISSP-ISSAP training syllabus, you will become well-versed with the following:

  • Design considerations, cryptography essentials, and integrated cryptographic solutions like API selection, Public Key Infrastructure (PKI), and more
  • Recovery solutions and security strategies
  • Business Continuity Planning (BCP), Disaster Recovery Planning (DRP), and Business Impact Analysis (BIA)
  • Physical security requirement assessment, security considerations, & solutions evaluation
  • Core concepts of access control techniques, systems, and access management architecture
  • Implementation of cryptography to protect organisational information and data from external and internal threats 
  • How to select and deploy communication products that adhere to organisation standards and policies 

The syllabus

Module 1: Governance, Risk, and Compliance (GRC)

1.1 Identify legal, regulatory, organizational, and industry requirements
  • Applicable information security standards and guidelines
  • Third-party and contractual obligations (e.g., supply chain, outsourcing, partners)
  • Applicable sensitive/personal data standards, guidelines, and privacy regulations
  • Resilient solutions
1.2 Architecting for governance, risk, and compliance (GRC)
  • Identify key assets, business objectives, and stakeholders
  • Design monitoring and reporting (e.g., vulnerability management, compliance audit)
  • Design for auditability (e.g., determine regulatory, legislative, forensic requirements,
    segregation, high assurance systems)
  • Incorporate risk assessment artifacts
  • Advise risk treatment (e.g., mitigate, transfer, accept, avoid)

Module 2: Security Architecture Modeling

2.1 Identify security architecture approach
  • Scope (e.g., enterprise, cloud) and types (e.g., network, service-oriented architecture (SOA))
  • Frameworks (e.g., The Open Group Architecture Framework (TOGAF), Sherwood Applied
    Business Security Architecture (SABSA), service-oriented modeling framework)
  • Reference architectures and blueprints
  • Threat modeling frameworks (e.g., Spoofing, Tampering, Repudiation, Information Disclosure,
    Denial of Service, and Elevation of Privilege (STRIDE), Common Vulnerability Scoring System
    (CVSS), threat intelligence)
2.2 Verify and validate design (e.g., functional acceptance testing, regression)
  • Results of threat modeling (e.g., threat vectors, impact, probability)
  • Gaps
  • Alternative solutions/mitigations/compensating controls
  • Internal or external third-party (e.g., tabletop exercises, modeling and simulation, manual
    review of functions, peer review)
  • Code review methodology (e.g., dynamic, manual, static, source composition analysis)

Module 3: Infrastructure and System Security Architecture

3.1 Identify infrastructure and system security requirements
  • Deployment model (e.g., On-premises, cloud-based, hybrid)
  • Information technology (IT) and operational technology
  • Physical security (e.g., perimeter protection and internal zoning, fire suppression)
  • Infrastructure and system monitoring
  • Infrastructure and system cryptography
  • Application security (e.g., Requirements Traceability Matrix, security architecture
    documentation, secure coding)
3.2 Architect infrastructure and system security
  • Physical security control set (e.g., cameras, doors, system controllers)
  • Platform security (e.g., physical, virtual, container, firmware, operating system (OS))
  • Network security (e.g., wired/wireless, public/private, Internet of Things (IoT), management,
    firewalls, airgaps, software defined perimeters, virtual private network (VPN), Internet
    Protocol Security (IPsec), Network Access Control (NAC), Domain Name System (DNS), Network Time Protocol (NTP), Voice over Internet Protocol (VoIP), Web Application Firewall (WAF))
  • Storage security (e.g., direct attached, storage area network (SAN), network-attached storage
    (NAS), archival and removable media, encryption)
  • Data repository security (e.g., access control, encryption, redaction, masking)
  • Cloud security (e.g., public/private, Infrastructure as a Service (IaaS), Platform as a Service
    (PaaS), Software as a Service (SaaS))
  • Operational technology (e.g., industrial control system (ICS), Internet of Things (IoT),
    supervisory control and data acquisition (SCADA))
  • Endpoint security (e.g., bring your own device (BYOD), mobile, endpoint detection and response
    (EDR), host-based intrusion detection system (HIDS)/host-based intrusion prevention system
    (HIPS))
  • Secure shared services (e.g., e-mail, Voice over Internet Protocol (VoIP), unified
    communications)
  • Third-party integrations (e.g., internal/external, federation, application programming interface
    (API), virtual private network (VPN), Secure File Transfer Protocol (SFTP))
  • Infrastructure monitoring
  • Content monitoring (e.g., email, web, data, social media, data loss prevention (DLP))
  • Out-of-band communications (e.g., incident response, information technology (IT) system
    management, Business Continuity (BC)/disaster recovery (DR))
  • Evaluate applicability of security controls for system components (e.g., web client
    applications, proxy services, application services)
3.3 Architect infrastructure and system cryptographic solutions
  • Determine cryptographic design considerations and constraints (e.g., technologies, lifecycle,
    computational capabilities, algorithms, attack in system)
  • Determine cryptographic implementation (e.g., in-transit, in-use, at-rest)
  • Plan key management lifecycle (e.g., generation, storage, distribution)

Module 4: Identity and Access Management (IAM) Architecture

4.1 Architect identity lifecycle
  • Establish identity and verify (e.g., physical, logical)
  • Assign identifiers (e.g., to users, services, processes, devices, components)
  • Identity provisioning and de-provisioning (e.g., joiners, movers, and leavers process)
  • Identity management technologies
4.2 Architect identity authentication
  • Define authentication approach (e.g., single-factor, multi-factor, risk-based elevation)
  • Authentication protocols and technologies (e.g., Security Assertion Markup Language
    (SAML), Remote Authentication Dial-In User Service (RADIUS), Kerberos, Open
    Authorization (OAuth)
  • Authentication control protocols and technologies (e.g., eXtensible Access Control
    Markup Language (XACML), Lightweight Directory Access Protocol (LDAP))
  • Define trust relationships (e.g., federated, stand-alone)
4.3 Architect identity authorization
  • Authorization concepts and principles (e.g., discretionary/mandatory, Separation of
    Duties (SoD), least privilege, interactive, non-interactive)
  • Authorization models (e.g., physical, logical, administrative)
  • Authorization process and workflow (e.g., governance, issuance, periodic review,
    revocation, suspension)
  • Roles, rights, and responsibilities related to system, application, and data access
    control (e.g., groups, Digital Rights Management (DRM), trust relationships)
  • Management of privileged accounts (e.g., Privileged Access Management (PAM))
  • Authorization approach (e.g., single sign-on (SSO), rule-based, role-based,
    attribute-based, token, certificate)
4.4 Architect identity accounting
  • Determine accounting, analysis, and forensic requirements
  • Define audit events
  • Establish audit log alerts and notifications
  • Log management (e.g., log data retention, log data integrity)
  • Log analysis and reporting
  • Comply with policies and regulations (e.g., PCI-DSS, FISMA, HIPAA, GDPR)

Admission details

  • Visit Infosec Train's CISSP-ISSAP certification course webpage.
  • Then, scroll to the bottom and select the learning mode you prefer.
  • Click on 'Enrol Now' to access the application form and fill out the required data fields.
  • After you've provided all the details, tap the 'Submit Now' button to submit it.

Filling the form

You must provide accurate contact details in the application form for the CISSP-ISSAP training course. Enter your name, email ID, country of residence, and phone number. You're also required to fill out a small comment section.

Evaluation process

You can become a certified CISSP-ISSAP professional after passing the CISSP-ISSAP certification exam. There will be a total of 125 MCQ-based questions. You will need to complete the exam within three hours.

Besides, you must score a minimum of 700 points out of 1000 points to qualify for the certificate.

How it helps

With the CISSP-ISSAP certification, you will have the technical expertise and skills in security architecture needed to land a job as the chief security architect/analyst. Since it's a globally accepted credential, you can also use the certificate worldwide to validate your competency in information security and gain a competitive edge.

As a certified professional, you will know how to implement a sound and robust security programme to meet your organisational goals. Besides, the CISSP-ISSAP programme by Infosec Train is conducted by experienced and certified trainers and follows a tailor-made curriculum.

Instructors

Mr Prabh Nair
Instructor
Freelancer

FAQs

Is Infosec Train an authorised training partner of (ISC)2?

No. (ISC)2 does not authorise Infosec Train.

How many points do I need to pass this CISSP ISSAP certification exam?

Applicants are required to score at least 700 points in the CISSP-ISSAP exam to clear it.

Who can join the training?

Chief Technology Officers, Chief Security Officers, System and Network Designers, System Architects, and Business Analysts can join the training.

What will be the duration of the CISSP-ISSAP certification exam?

The exam will be for three hours.

What does CISSP-ISSAP stand for?

CISSP stands for Certified Information Systems Security Professional.

Trending Courses

Popular Courses

Popular Platforms

Learn more about the Courses